Compliance as a Set of State-Defined Rules

Lecture 12 min.



Compliance (from the English word "compliance", meaning agreement or conformity; derived from the verb to comply) literally means ( in English) action in accordance with a request or command; obedience (compliance is an action in accordance with a request or command, obedience). "Compliance" means conformity to certain internal or external requirements or norms.

Compliance is understood as the part of an organization's management/control system that deals with compliance risks, that is, the risks of non-conformity and failure to comply with the requirements of legislation, regulatory documents, and the rules and standards of supervisory bodies, industry associations and self-regulatory organizations, codes of conduct, and so on. Compliance risks may ultimately manifest themselves in the form of legal or regulatory sanctions and financial or reputational losses as a result of non-conformity with laws, rules and standards in the sphere of compliance.

In general, compliance means conformity to a rule, such as a specification, policy , standard or law. Compliance describes the goal that organizations strive to achieve in their efforts to ensure that they are aware of relevant laws , policies and regulations and take steps to comply with them . With the growing number of regulations and the need for operational transparency, organizations increasingly apply consolidated and harmonized sets of compliance controls. This approach is used to ensure that all necessary governance requirements are met without unnecessary duplication of effort and of resource activity.

Rules and accrediting bodies differ by sector, for example PCI-DSS and GLBA in the financial industry, FISMA for US federal agencies, HACCP (Hazard Analysis and Critical Control Points) for the food and beverage industry, and the Joint Commission and HIPAA in healthcare. In some cases other compliance frameworks (such as COBIT ) or even standards ( NIST ) inform how to comply with the rules.

Some organizations keep compliance data - all data owned by or relating to the enterprise, or included in law, that can be used to implement or demonstrate compliance - in a separate repository in order to meet reporting requirements. Compliance software is increasingly being deployed to help companies manage their compliance data more efficiently. This repository may include computations, data transfers and audit logs.

Today compliance is a line of professional activity brought into Russian organizations by large Western companies . It exists mainly in the financial and banking sector, although it is not limited to it. Units that carry out the conformity-checking function are usually called "Compliance" or "Compliance Control". In 2014 the Bank of Russia adopted amendments to Regulation No. 242-P, under which all banks are required to establish an internal control service that essentially performs the functions of compliance control (management of compliance risks or, in the terminology of 242-P, regulatory risks).

In medicine, compliance is therapeutic cooperation. It means a measure characterizing how correctly a patient follows the doctor's recommendations ;

(in pulmonology) a measure of the distensibility of lung tissue

Regulatory compliance depends not only on the industry but also on the region. For example, financial, research and pharmaceutical regulators in one country may be similar to those in another country but differ in particularly significant nuances. These similarities and differences are often the product of a "response to changing goals and requirements in different countries, industries and political contexts".

Australia

Australia's main financial services regulators for deposits, insurance and superannuation include the Reserve Bank of Australia (RBA), the Australian Prudential Regulation Authority (APRA), the Australian Securities and Investments Commission (ASIC), and the Australian Competition and Consumer Commission (ACCC). These regulators help ensure that financial institutions keep their promises, that information about transactions is well documented, and that competition is fair, protecting consumers. APRA in particular is concerned with superannuation and its regulation, including new rules requiring superannuation fund trustees to demonstrate to APRA that they have adequate resources (human, technological and financial), risk management systems, and the appropriate skills and knowledge to run a superannuation fund, and that the people running them are "fit and proper".

Other key regulators in Australia include the Australian Communications and Media Authority (ACMA) for broadcasting, the internet and communications; the Clean Energy Regulator for "monitoring, facilitating and enforcing compliance" with the energy and carbon emissions schemes; and the Therapeutic Goods Administration for medicines, devices and biologicals;

Australian organizations seeking to comply with various regulations can turn to AS ISO 19600:2015 (which replaces AS 3806-2006). This standard assists organizations in compliance management, placing "emphasis on the organizational elements needed to support compliance", while also recognizing the need for continual improvement .

Canada

In Canada, federal regulation of deposits, insurance and pensions is handled by two independent bodies: OSFI, under the Bank Act, and FINTRAC, established under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act of 2001 (PCMLTFA). These groups protect consumers, regulate how risks are controlled and managed, and investigate illegal activities such as money laundering and terrorist financing. ]At the provincial level, each province maintains separate laws and agencies. Unlike any other major federation, Canada has no securities regulator at the federal government level. Provincial and territorial regulators work together to coordinate and harmonize the regulation of Canadian capital markets through the Canadian Securities Administrators (CSA).

Other key regulators in Canada include the Canadian Food Inspection Agency (CFIA) for food safety and animal and plant health; Health Canada for public health; and Environment and Climate Change Canada for the environment and sustainable energy.

Canadian organizations seeking to comply with various regulations can turn to ISO 19600:2014 , the international compliance standard, which "provides guidance for establishing, developing, implementing, evaluating, maintaining and improving an effective and responsive compliance management system within an organization". For more specific guidance, for example for financial institutions, the Canadian Regulatory Compliance Management guideline E-13 provides specific tactics for managing compliance risk.

India

In India, regulation is carried out at three levels: central, state and local. India leans toward centralized regulation, especially with regard to financial institutions and foreign funds. Compliance norms differ by industry segment as well as by geographic composition. Most rules fall into the following broad categories: economic regulation, public-interest regulation and environmental regulation. India is also characterized by poor compliance - according to reports, only about 65% of companies fully comply with the rules.

Singapore

The Monetary Authority of Singapore is Singapore's central bank and financial regulatory authority. It administers the various laws relating to money, banking, insurance, securities and the financial sector in general, as well as the issuance of currency .

United Kingdom

In the United Kingdom there is extensive regulation , some of which derives from European Union law . Different areas are overseen by different bodies, such as the Financial Conduct Authority (FCA), the Environment Agency , the Scottish Environment Protection Agency , the Information Commissioner's Office , the Care Quality Commission , and others: see List of regulators in the United Kingdom .

Important regulatory compliance issues for all large and small organizations include the Data Protection Act 1998 and, for the public sector, the Freedom of Information Act 2000 .

Russia

The concept of compliance risk as applied to the banking sector is defined in Russian legislation in Bank of Russia Regulation 242-P. Compliance risk is understood as the risk of a credit institution incurring losses as a result of failure to comply with the legislation of the Russian Federation, the credit institution's internal documents, or the standards of self-regulatory organizations (if such standards or rules are binding on the credit institution), as well as a result of sanctions and/or other enforcement measures applied by supervisory bodies. This risk is also called regulatory risk.

Financial compliance

The UK Corporate Governance Code (formerly the Combined Code) is issued by the Financial Reporting Council (FRC) and "sets standards of good practice in relation to board leadership and effectiveness, remuneration, accountability and relations with shareholders." All companies with a premium listing of equity shares in the UK are required under the Listing Rules to report in their annual report and accounts on how they have applied the Combined Code. (In this respect the Codes are most similar to the US Sarbanes-Oxley Act .)

Compliance as a Set of State-Defined Rules

The UK regulatory framework requires all its publicly registered companies to provide specific content in the primary financial statements that must appear in the annual report, including the balance sheet, the statement of comprehensive income and the statement of changes in equity, as well as the cash flow statement, as required under international accounting standards. It also demonstrates the relationships that exist between shareholders, management and independent audit teams. Financial statements must be prepared using a particular set of rules and provisions, so companies are permitted to apply the provisions of company law, International Financial Reporting Standards (IFRS), and the rules of the UK stock exchange as directed by the FCA. It is also possible that shareholders may not understand the figures presented in the various financial statements, so it is very important for the board of directors to provide notes on accounting policies, as well as other explanatory notes, to help them better understand the report.

Challenges

Data retention is part of regulatory compliance, which in many cases proves to be a problem. The security provided by compliance with industry regulations may appear to conflict with preserving user privacy. Data retention laws and regulations require data owners and other service providers to keep detailed records of user activity for longer than is needed for ordinary business operations. These requirements have been challenged by privacy advocates. [25]

Compliance in this area becomes very difficult. Laws such as the CAN-SPAM Act and the Fair Credit Reporting Act in the US require that businesses give people the right to be forgotten . [ In other words, they must remove people from marketing lists if required, tell them when and why they may pass personal information to third parties, or at least ask permission before sharing that data. Now that new laws are coming out requiring longer data retention regardless of individual wishes, this may create some real difficulties.

United States

Corporate scandals and failures, such as the Enron reputational risk case in 2001, intensified calls for stricter compliance and regulation, especially for public companies. The most significant recent legislative changes in this context were the Sarbanes-Oxley Act, drafted by two US congressmen, Senator Paul Sarbanes and Representative Michael Oxley, in 2002, which established significantly stricter personal liability of top corporate management for the accuracy of financial statements; and the Dodd-Frank Wall Street Reform and Consumer Protection Act .

The Office of Foreign Assets Control (OFAC) is an agency of the United States Department of the Treasury under the auspices of the Under Secretary of the Treasury for Terrorism and Financial Intelligence. OFAC administers and enforces economic and trade sanctions based on US foreign policy and national security goals against targeted foreign states, organizations and individuals.

Compliance in the US usually means compliance with laws and regulations. These laws and regulations may carry criminal or civil liability. Defining what constitutes an effective compliance program has been difficult. Most authors, however, continue to refer to the guidelines of the US Sentencing Commission in Chapter 8 of the Federal Sentencing Guidelines.

On October 12, 2006, the US Small Business Administration relaunched Business.gov (later Business.USA.gov and finally SBA.Gov) , which provides a single point of access to government services and information that helps businesses comply with government regulations.

The US Occupational Safety and Health Administration (OSHA) was created by Congress to ensure safe and healthy working conditions for working men and women by setting and enforcing standards and by providing training, outreach, education and assistance. OSHA regularly enforces laws and regulations in the following areas: construction, maritime, agriculture and record-keeping.

Standards

The International Organization for Standardization (ISO) and its ISO 19600 standard is one of the main international standards for how businesses deal with regulatory requirements, providing a reminder of how compliance and risk should work together, as "colleagues" sharing a common framework, with some nuances to account for their differences. ISO also develops international standards, such as ISO/IEC 27002, to help organizations ensure regulatory compliance through best practices in security management and assurance. [32]

Some local or international specialized organizations, such as the American Society of Mechanical Engineers (ASME), also develop standards and regulatory documents. In this way they provide a wide range of rules and directives to ensure that products meet safety, protection or design standards.

See also

  • Business Motivation Model . A standard for recording corporate governance and regulatory compliance actions
  • Chief compliance officer
  • Governance, risk management and compliance
  • Compliance and ethics program
  • International Compliance Association
  • Due diligence
created: 2021-12-06
updated: 2026-09-29
155



Was this answer useful?
Choose a quick rating so we can improve the next answer for you.
How satisfied are you?


Comments

To leave a comment

If you have any suggestion, idea, thanks or comment, feel free to write. We really value feedback and are glad to hear your opinion.
To reply

Lectures and tutorial on "World economy"

Terms: World economy